CrowdStrike Falcon Malware - Incident Enrichment
This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook enables enriching CrowdStrike Falcon incidents by pivoting to their detections as well as mapping all the relevant data to the Cortex XSOAR incident fields.
- Pack
- CrowdStrikeFalcon
- Tasks
- 27
Inputs
- DetectionOrCaseID — The ID of the CrowdStrike detection or Case.
Outputs
- CrowdStrike — CrowdStrike Detection or Incident details.
- Endpoint — Endpoint details.
- CrowdStrike.FoundDetections — Indicates whether detections were found.
Commands used
- endpoint
- extractIndicators
- setIncident